CVE-2024-23446: Elastic Kibana

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized to call this API may obtain unauthorized access to documents if their roles are configured with DLS or FLS against the aforementioned index.

Affected products

  • Elastic Kibana: from 8.0.0, before 8.12.1 (fixed in 8.12.1)

Published 2024-02-07. Last modified 2026-06-17.